This Privacy Policy is effective as of and was last updated on . We may update it occasionally — changes will be reflected here with a revised date.
We collect only what’s necessary to operate our leisure reading platform:
- Anonymous usage data: Pages visited, session duration, and referral source — collected via lightweight analytics (no cookies or identifiers required).
- Optional account data: If you create an account, we store only your email address and an encrypted password. No names, birthdays, or phone numbers are requested or stored.
- Preference signals: Font size, theme (light/dark), and reading progress — saved locally in your browser unless you opt into cloud sync (clearly labeled during setup).
We do not collect or process sensitive personal data (e.g., health, political views, biometrics), nor do we sell, rent, or trade any user information.
We use data solely to enhance your reading experience:
- Deliver personalized recommendations based on genres and titles you explore — processed entirely on-device when possible.
- Improve site performance, fix bugs, and refine layout and navigation.
- Support optional features like bookmark syncing or offline reading — always with explicit consent.
- Comply with legal obligations and respond to lawful requests — only after verifying validity and scope.
All processing adheres to GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity & confidentiality.
We integrate minimal, privacy-conscious services:
- Google AdSense: Used only for non-personalized ads (disabled by default for EU users). No ad personalization cookies are set unless explicitly consented to via our cookie banner.
- Cloudflare: For security, performance, and DDoS protection — no tracking or data logging beyond standard CDN logs (retained ≤24 hours).
- Analytics: Optional, anonymized event tracking (e.g., “Chapter X loaded”) — disabled by default and never tied to individuals.
We do not use Facebook Pixel, Google Analytics (GA4), or any third-party trackers that violate GDPR or CCPA standards.
You have full control over your data:
- View, export, or delete your account and associated data anytime from your account settings.
- Opt out of marketing emails instantly using the unsubscribe link in every message.
- Disable cookies or local storage in your browser — the site remains fully functional for reading (account features may require re-authentication).
- Submit a data subject request via — we respond within one business week.
We prioritize security:
- Passwords are hashed using bcrypt with per-user salts; plain-text storage never occurs.
- Account data is encrypted at rest (AES-256) and in transit (TLS 1.3+).
- Server access is restricted, audited, and rotated regularly.
- We retain account data only as long as needed — typically deleted within 30 days after account deletion request.
Our service is intended for general audiences aged 13 and older. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will promptly delete the data.